Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
A prolific hacking group has taken credit for last week’s cyberattack against U.S. pharmaceutical distribution giant McKesson, leading to the latest spill of highly sensitive health data by an American healthcare company in recent months.
McKesson confirmed Friday in a statement on its website that hackers broke into several of its cloud-hosted accounts earlier in the week and exfiltrated data, and that the company expected “intermittent service degradation” related to the incident. In a separate notice to customers, the company’s chief technology officer, Francisco Fraga, said the stolen data relates to its oncology & multispecialty and medical-surgical units.
The Texas-based company is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers across the United States, and as such handles a large amount of patient data.
The ShinyHunters hacking group — one of the most active data-extortion crews of the past two years — told TechCrunch that it hacked the company’s cloud environment by tricking several employees into granting the hackers’ access to McKesson’s network by using phishing and social engineering tricks, which the group is known for.
The hackers said they stole a range of personal information, such as names, addresses, and Social Security numbers, as well as protected health information, including diagnoses, medications, allergies, and patient notes. The hackers say they took millions of rows of patient data from the company’s cloud-hosted Snowflake and Salesforce environments, but that they are unsure of how many individuals are ultimately affected.
The stolen data also included McKesson employees’ information, such as home addresses.
ShinyHunters shared screenshots and a sample of the stolen data with TechCrunch, and we verified a small subset of it against public records.
Bleeping Computer, which first reported the link to the ShinyHunters hacking group, said the hackers demanded a $55 million ransom from the company in exchange for not publicly releasing the stolen files.
A spokesperson for McKesson did not respond to TechCrunch’s request for comment on Monday.
McKesson is the latest healthcare company or medical device maker to be targeted in a string of cyberattacks in recent months, as hackers aim to steal large amounts of sensitive medical and health data that they can use to extort the companies into paying a ransom to keep it from being published.
Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of the company’s network offline. The cyberattack had a similar effect to an incident earlier this year at another medical device maker Stryker , in which hackers abused a company’s internal tools to remotely wipe thousands of employee devices.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on techcrunch.com — the content belongs to TechCrunch.